GDPR impacts technology, tools, people, and processes
To ensure compliance and an ability to meet the responsibilities of GDPR, organizations must recognize that they will need to implement not only the right technology, or tools, but also the right people and processes.
People required are:
- Data subjects.
- People who understand that GDPR implementation is everyone's responsibility.
- Data protection officer(s).
- Information asset owners.
- People who will be responsive to inbound requests.
For processes, key questions are:
- How will you manage, process, and execute inbound requests to ensure you are meeting GDPR requirements as a data controller?
- How will you evidence your compliance? Consider factors such as being timely, auditable, and having the ability to report.
- How do you know how well you are performing against your requirements?
For tools, key questions are:
- Where will you track and manage the GDPR process and requests?
- How will you accept GDPR requests from data subjects?
- How will you allow...